[nonimo]
EN
Download

AI in local government: when your prompts are public records

· Updated · Written and maintained by Joaquín Trapero, Nonimo

If you work for a city or a county in the United States and you paste a resident’s email into a chatbot, two things happen at once. Their information leaves your building, and you create a record that somebody can ask for. In Washington state somebody did ask, and cities handed over thousands of pages of staff chat logs.

That second half is what almost no local government AI policy is written for. Most are written about accuracy: check the output, do not trust the citations. Those are real problems, but they are not the one that puts your city’s name in a story.

This guide covers what public records law does to a prompt, what resident data is at stake, and which rules bind a US agency and which only look like they do. Everything comes from a primary source, checked on the date given in the sources at the end. For a private firm, the question becomes whether pasting client data into a chatbot is a breach.

How staff use AI in local government, and what a records request found

Between 2023 and 2025, Cascade PBS and KNKX filed public records requests with nearly a dozen Washington cities for two years of ChatGPT logs. Bellingham and Everett answered fastest and most completely, and the reporting notes they were chosen for that reason rather than for being unusual.

What came back was thousands of pages from nearly every department. Reporter Nate Sanford told Poynter that both cities emailed every single employee asking them to export their ChatGPT history, and the request took about five months to close.

The mayor’s letter that a chatbot wrote

When the Lummi Nation applied for state grant funding for a crime victims coordinator, Bellingham Mayor Kim Lund sent a letter of support to the Washington Department of Commerce. Records show her assistant fed the request for proposals into ChatGPT and asked it to write the letter. About half the sentences in the version that was sent matched the chatbot’s output.

In Everett, a letter from Mayor Cassie Franklin asking a member of Congress to sign on to a drone bill was generated in full from a prompt of three sentences. Franklin said she could not remember whether staff had told her.

The resident who found her own email inside a prompt

The case that should worry a records officer is smaller. After a February snowfall, a Bellingham resident named Bre Garcia emailed Public Works to complain that her street had not been plowed. A staffer copied her email into ChatGPT and asked for a reply acknowledging the concerns. Four words were added to what came back.

Cascade PBS sent Garcia a screenshot of her own email inside a city official’s chat history, obtained through the records request. Her complaint, her street, her name, disclosed to a third party and then to the public. Nobody broke a rule that anybody had written down.

What the logs showedWhere
A senior citizen’s email about unaffordable utilities, pasted in for a sympathetic replyBellingham
A draft tenant protection ordinance, uploaded wholeEverett
Talking points and speeches drafted for the mayorEverett
Staff writing cover letters to apply for other jobsBoth
Chats redacted for city code tracking homeless encampments, and an active police investigationBoth

Cascade PBS and KNKX, August 26 and 27, 2025, from public records.

Read that list as an inventory rather than a scandal. It is a workforce doing ordinary work in a tool nobody told them was a filing cabinet, the same pattern we found in what ChatGPT does with what you type.

Your prompts are public records, and a personal account does not change that

Private sector advice worries about the vendor. Public sector reality adds a second channel, and it points outward.

The Washington answer is one word

Washington State Archives publishes short advice sheets for state and local agencies. One of them, issued June 2024, is titled Are Generative AI Interactions Public Records? It answers in a single word.

YES. If a generative AI interaction (input and output) relates to public business, then it is a public record under RCW 40.14.010.

Washington State Archives, Records Management Advice, June 2024

The definition it quotes covers any document, regardless of physical form or characteristics, made or received by an agency in connection with the transaction of public business. A prompt is a document. So is the answer. So is a meeting summary from conferencing software, or an assistant’s draft inside a mail client. What each major assistant retains and for how long then decides whether you can still produce them when the request lands.

A personal account is not a side door

The same sheet answers the next question. If you use a personal AI account to conduct business for your agency, you are creating public records, and it does not matter whether the account is personal or issued by the agency.

That undoes the most common workaround: the employee who uses their own subscription because IT has not approved anything yet. It does not move the record outside the agency. It moves it somewhere the agency cannot search, which is worse.

California gets there by a different route

California Government Code section 7920.530 defines public records as any writing containing information relating to the conduct of the public’s business prepared, owned, used, or retained by any state or local agency, regardless of physical form. The word that carries the weight is used, and nothing in it turns on the software.

Every state has a law of this shape and no two are identical. Ask your own records officer, in writing, before you assume otherwise.

Retention is decided by content, not by format

A second Washington advice sheet, also June 2024, asks whether all AI records can be treated as transitory. Its answer is yes and no: retention depends on the content and function of the record, not on the chat window. Using a chatbot as a sounding board is one thing. Using it to draft an ordinance is another, and the ordinance schedule applies. The sheet adds, bluntly, that retaining everything is a strategy for chaos.

The transitory label is where agencies instinctively reach. In Bellingham, the mayor said her own chats were not released because she had not been logged in, and maintained that her use was transitory. Whether that holds is a question for a records officer, not for the person who wrote the prompt.

The paste itself may already be a disclosure

WaTech’s guidelines point at RCW 42.52.050, the state ethics law: no state officer or employee may disclose confidential information to any person not entitled or authorized to receive it. The law defines a person as any individual, partnership, association, corporation, firm, institution or other entity, and WaTech draws the conclusion itself.

This definition would include commercial generative AI tools freely available in the market.

WaTech, Interim Guidelines for Purposeful and Responsible Use of Generative AI, State CIO adopted August 8, 2023

If the text is confidential and the chatbot is a person under the statute, the paste is the disclosure. Nothing has to leak. The guidance is written for state employees, and its force elsewhere depends on your own state’s statutes, but it is worth putting in front of a city attorney. The city’s own HR files add a federal layer: the ADA’s rules on who may be told about an employee’s condition names no chatbot.

  1. Does the prompt, or the answer it got, relate to public business?

    YesIt is a public record, input and output alike. In Washington that is RCW 40.14.010.

  2. Was it typed into a personal account?

    YesStill a public record. It does not matter whether the account is personal or issued by the agency.

  3. Did the chat do real work, such as drafting an ordinance?

    YesThe retention schedule for that content applies. Retention follows content and function, not the chat window.

    NoIt may be transitory, but that call belongs to a records officer, not to the person who wrote the prompt.

  4. Does an exemption cover what is in it?

    YesThose parts can be redacted, as the encampment code and the police investigation were in the Washington logs.

    NoIt is disclosed. Embarrassing is not an exemption, and neither is private.

A second exit comes before all four: for Washington state employees, WaTech reads RCW 42.52.050 as treating a commercial chatbot as a person, so pasting confidential text is already a disclosure.

What happens to a prompt in a Washington agency, from the State Archives advice sheets of June 2024 and WaTech's guidelines of August 8, 2023. Other states differ in the detail

Redaction is narrower than sensitive, and that gap is the whole problem

Some of the Bellingham and Everett chat histories were redacted because the user had put confidential information into the chatbot: city code for tracking homeless encampments, material about an active police investigation. But the same reporting records the fact that should decide your policy: many records did not meet the legal threshold for redaction and still contained personal information never meant for public consumption.

Exemptions are narrow and enumerated. A resident’s complaint about her own street, with her name on it, generally is not exempt. Seattle’s AI policy states the rule plainly: regardless of the retention period, if records responsive to a public disclosure request exist, they must be disclosed.

And somebody has to read every line of it

A redaction decision is made line by line, by a person, against a list of exemptions, and chat logs are the worst shape for that work: unstructured, wandering between a spreadsheet formula and a case file in one conversation. In Washington the first responses arrived as phone screenshots with no dates, and the reporter ended up sending export instructions.

Seattle’s policy makes departments responsible for searching for and retrieving records created with AI products when a disclosure request is received. The cheapest version of that duty is the one with less to search; the second cheapest is the one where the tool has an export button.

So the control has to sit upstream. Once the resident’s text is in the prompt, the prompt is the record. It is the same asymmetry that makes a paste hard to undo in any regulated setting, plus the records channel.

The resident data a city holds, and which parts of it actually bite

A finance department, a police department, a permit counter, a benefits caseworker and a library all sit under one budget, and one IT team writes one policy for all of them.

The identifier is rarely the risk

In city work, Social Security numbers are rarely the whole exposure. A single address on a single date, attached to a single complaint, identifies a household to anyone on that street.

So the useful question is not only are there identifiers in this text. It is also would a neighbor know who this is, and that stays a human judgment. What the law makes of a masking pass is answered in which American rules care what you removed.

Three functions where a separate rulebook takes over

  1. Police and prosecution. Criminal justice information sits under the FBI CJIS Security Policy, and your agency already has someone accountable for it. That person answers this question, not IT.
  2. Anything clinical. A county clinic, a jail infirmary or an ambulance service may be a HIPAA covered entity. Where it is, the contract is the whole game: the assistant vendors state that their ordinary plans are outside any business associate agreement until somebody activates one, which we set out for Claude and for Copilot.
  3. Schools and libraries. Student records bring FERPA, and library borrowing records are separately protected in many states. A school district that shares city IT does not inherit the city’s answers.

Each already has an owner. A citywide policy should name them, so a caseworker does not have to work out which rulebook applies.

No federal privacy law reaches your city, and your state’s probably exempts it

Ask a local government manager which privacy law governs their AI use and you will often hear the CCPA. It almost certainly does not. California Civil Code section 1798.140 defines a business as a legal entity organized or operated for the profit or financial benefit of its shareholders or other owners, above one of three thresholds. A city is not.

Other state comprehensive privacy laws use definitions of the same shape; read yours, because the exemptions differ.

There is also no federal data protection regulator. In American local government the consequence arrives as a records request, a council meeting, a local reporter, a plaintiff’s lawyer, or the state attorney general using consumer protection powers.

Commonly assumedActually applies to a US agency
CCPA or a state comprehensive privacy lawUsually not: the definitions are written around businesses run for profit
A federal data protection regulatorDoes not exist
GDPROnly if you process data of people in the EU
Nothing, thereforeYour state public records act, always
Your state records retention schedule, always
HIPAA, FERPA and CJIS where the function triggers them

Definitions read September 20, 2026, in the statutes cited in the sources.

A vendor deck that says CCPA compliant is answering a question you did not ask. The risk your insurer will ask about is closer to our guide on what cyber insurance does not cover.

State AI laws: Texas already preempts your ordinance, Colorado starts in 2027

Texas: your city may not write its own AI rules

The Texas Responsible Artificial Intelligence Governance Act, HB 149, took effect on January 1, 2026, and its most restrictive provisions are aimed at government.

Section 552.051 requires a governmental agency that makes an AI system available to interact with consumers to disclose that fact before or at the time of interaction, even where it would be obvious to a reasonable person. Section 552.053 prohibits a governmental entity from using AI to assign a social score. Section 552.054 restricts government use of AI to uniquely identify individuals from biometric data or scraped images without consent.

Then section 552.003: the chapter supersedes and preempts any ordinance, resolution, rule or other regulation adopted by a political subdivision regarding the use of AI systems. Read narrowly, that ends local AI ordinances. Read widely, rule or other regulation could reach an internal staff policy. Ask your city attorney before the draft goes to council.

Colorado: essential government services are a covered domain

The 2024 Colorado AI Act, SB 24-205, was set for February 1, 2026, delayed in a special session to June 30, 2026, and then repealed and reenacted before that date arrived. SB 26-189 was signed on May 14, 2026, and its duties begin on January 1, 2027.

It regulates automated decision-making technology that materially influences a consequential decision, and its covered domains include essential government services and public benefits. Deployers owe consumers notice at the point of interaction, a plain-language explanation within 30 days of an adverse outcome, a right to correction and a right to meaningful human review, and must keep compliance records for at least three years.

Whether a municipality is a deployer is a question for your attorney; the attorney general is directed to adopt clarifying rules by January 1, 2027.

Washington: disclosure arrives on February 1, 2027

Washington HB 1170 requires government agencies to notify consumers when they are interacting with certain AI systems, and requires providers of certain systems to include provenance data in the content they create. It takes effect on February 1, 2027.

2026Texas disclosure and preemption, in force
2027Colorado ADMT duties begin
2027Washington agency disclosure begins
Effective dates read from the bills on September 20, 2026. Colorado replaced its 2024 act before it ever took effect

Write your internal policy to survive that churn, naming behavior rather than citing a statute that may not exist next year, the way a good staff AI policy is written.

Above all three, one executive order with money attached

There is no comprehensive federal AI statute. Executive Order 14365, signed December 11, 2025, and titled Ensuring a National Policy Framework for Artificial Intelligence, directs the Attorney General to establish an AI Litigation Task Force whose sole responsibility is to challenge state AI laws inconsistent with the order’s policy, and directs Commerce to publish an evaluation identifying onerous state laws.

What the order sets upWhy a county cares
A DOJ task force to sue states over AI lawsThe obligation you are budgeting for may not survive the year
A Commerce list of onerous state AI lawsBeing listed is what triggers the two rows below
BEAD broadband funds withheld from listed statesNondeployment money passes through the state to you
Discretionary federal grants conditioned on state AI policyThe largest and least predictable channel

Executive Order 14365, sections 3 to 5, read September 20, 2026.

What has not moved is your state’s public records act and your retention schedule. They are the most stable obligations on this page, and your written policy should be built around them.

NIST AI RMF and the GovAI Coalition, and what each is actually for

The framework everyone aligns to

The NIST AI Risk Management Framework was released on January 26, 2023. It is voluntary, it is not a certification, and nobody enforces it. It gives a council, an auditor and a vendor a shared vocabulary. NIST added a Generative AI Profile, AI 600-1, on July 26, 2024. Washington’s interim guidelines for state employees, adopted by the State CIO on August 8, 2023, say the state intends to follow the NIST principles.

NIST states that AI RMF 1.0 is being revised as part of the White House AI Action Plan. If your policy cites a version number, it will need rereading, the same maintenance problem every dated claim in our guides carries.

The templates a small agency can just take

The GovAI Coalition began at the City of San Jose in 2023, after vendors proved reluctant to answer questions about privacy and data usage, held its first meeting with about 50 agencies in November 2023, and went public on March 13, 2024.

It publishes, free and adoptable, an AI policy, an AI governance handbook with an algorithmic impact assessment form, an AI incident response plan, a data sharing agreement, upskilling playbooks, an AI FactSheet for vendors and a vendor agreement, all intentionally aligned to the NIST framework. Seattle’s policy credits material developed through the coordinated efforts of over 140 state and local agencies in the Coalition.

140+
state and local agencies in the GovAI Coalition, whose coordinated work Seattle credits, in part, for its own AI policy. City of Seattle, POL-211, approved May 6, 2025

Everett said it was modeling its AI policy on a GovAI Coalition template. That is a better path than Bellingham’s, whose draft AI policy the records show was written with the help of ChatGPT.

Which tool and which account: the decision that does most of the work

Everett told staff to use Microsoft Copilot only, with a special exemption needed for anything else. Bellingham took what its IT director called a permissive approach, encouraging Copilot while allowing other tools. Everett’s IT director gave the reason: more safeguards than consumer ChatGPT, integration with systems the city already runs, and a government version hosted in the United States.

That is defensible, but it changes the contract and the default, not the physics. The commercial terms on a work account differ from the consumer ones, as the documentation for Copilot and for Claude sets out.

Moving to a government work accountDoes it change?
Whether your text trains the vendor’s model by defaultYes, that is the main thing it buys
Who you have a contract with, and what it promisesYes
Whether an admin can search and export the historyUsually yes, and that is the records answer
Whether the prompt is a public recordNo
Whether a caseworker can paste a case fileNo

Read from each vendor’s own documentation in September 2026, and listed in the guides at the end.

A procurement decision is a good decision and it is not a control. A blanket ban fails quietly: the Washington logs show two years of unauthorized adoption, and prohibition without a sanctioned tool produces the personal account your records officer cannot search.

Who has to sign it, and why that is not just IT

Everett’s draft AI policy went to the city employee unions for feedback before it was finalized, and then to the mayor. An AI policy sets rules about how people do their jobs and creates grounds for discipline, which in most American local government is a subject of bargaining.

Skip that step and the policy gets challenged the first time it is enforced. Add the records officer and the attorney: three signatures on a short document beat one on a long one.

The staff policy, and the five things it has to say

Most policies on AI in local government are longer than they need to be. Five clauses carry the weight.

ClauseWhat it has to say
AccountWhich account each person signs in with, named, and that a personal account is never used for city work
ToolWhich tools are sanctioned, and how an exemption is requested and recorded
Never listThe categories that may never be pasted, written in your departments’ own words
RecordsThat prompts and outputs are public records, subject to retention and disclosure
DisclosureWhen AI assistance is cited on work that reaches the public, and in what form

Structure drawn from the GovAI Coalition AI policy template and the Washington and Seattle policies cited in the sources.

The disclosure clause is the one that gets ignored

Everett’s IT department issued guidance in July 2024 requiring that AI-generated material released to external audiences for public policy decisions be clearly labeled. The records show unlabeled AI content produced after that, including the mayor’s letter to Congress. Washington’s state guidelines give a sample line naming the model, quoting the prompt and naming the reviewer, and the reporting found that guidance does not appear to be widely followed.

A disclosure rule nobody follows creates a documented expectation you are visibly failing. Make it narrow enough to comply with, usually citing assistance only where AI did more than refine language, or do not write it.

The never list is the only clause you cannot copy

Ask each department head for three things their staff handle that should never be pasted anywhere: the shelter intake field, the code complaint that names a neighbor, the applicant’s accommodation request. Put those lines in the policy, next to the general ones from the template. Write them as things: Never paste a shelter intake form is a rule a person can follow at eight in the morning; never process special category personal data makes them guess.

What to ask for before you sign a public contract

The GovAI Coalition exists because San Jose found vendors unwilling to answer basic questions, and its templates are the answer.

Ask forWhy it matters here
A completed AI FactSheetModel, training data, known limitations, in one comparable document
A written statement on trainingWhether your data trains the vendor’s models, and under which plan
Export and search capabilityYou have to produce these records on request, at your cost
Retention and deletion termsYour schedule governs, not the vendor’s default
Incident notification termsWho tells you, how fast, and in what form
Named subprocessorsThe model behind the product is often a third party

The GovAI Coalition publishes free templates for the FactSheet, a vendor agreement, a data sharing agreement and an incident response plan.

The third row is the one local government adds, and the one most likely missing from a demo. A tool that holds records you must produce, with no export and no admin search, is an unfunded mandate.

Ask for it in the contract, and ask what it produces: a file per user, a date range, a format a records officer can open. Several of these questions are also on insurers’ renewal forms, as set out in the cyber questionnaire guide.

Answering a resident without their file leaving the building

Take the Bellingham snowplow complaint. A staffer wants help writing a reply that is polite, accurate and short. That is a legitimate use. The staffer pasted the whole email; the model needed almost none of it.

In the resident’s emailDoes the model need it?
Her name and email addressNo
Her street and blockNo, unless the reply quotes it, and it should not
The date and the weatherYes, in general terms
The substance of the complaintYes
What the city actually didYes, and it comes from you, not from her

A prompt describing a resident who complained that a residential street was not plowed during a snow event, asking for a reply that acknowledges the concern and states that crews made multiple passes, produces the same paragraph. It is still a public record, but one that identifies nobody.

It is also still a form letter. Garcia’s objection was that nobody appeared to have read what she said. Removing her name does not fix that; somebody reading the email and the draft before it goes does. The same care applies whichever assistant you use, including Gemini.

What a tool fixes here, and what no tool fixes, including ours

Software of this kind can mask identifiers before text is sent, show what it changed so a person can overrule it, and leave evidence that the control was on. It cannot decide a document is too sensitive to send at all, or see that an address and a date identify a household. And it cannot make an agency compliant, because compliance is not a property software has.

The chatbot you point at residents is a different risk

A chatbot on the city website answering residents fails in the opposite direction. New York City launched MyCity in October 2023, running on Microsoft technology, to help business owners navigate city rules. Five months later The Markup tested it.

What the bot saidWhat the law says
Landlords need not accept housing vouchersThe city forbids source of income discrimination, with a narrow exception for small buildings where the owner lives
A restaurant can go cashlessA 2020 city council law requires businesses to accept cash
An employer can take a cut of workers’ tipsIt cannot, though tips can sometimes count toward the minimum wage

The Markup, March 29, 2024, from its own testing of the MyCity bot.

One reporter was told landlords did have to accept vouchers; ten Markup staffers then asked and all ten were told the opposite. A bot that faces residents is a publication that speaks in your name, and its approval belongs to your attorney rather than to IT.

What our engine does and does not do on American paper

An SSN or an ITIN written with its usual dashes is caught even with nothing in front of it, and the other American identifiers are caught behind their label, so SSN: 900000000 is masked as well. Every one it catches becomes a general REFERENCE tag, shown on screen with a way to undo it, so the model knows a number stood there without seeing it.

The American numbers it takes out, from the SSN to the medical record number, are listed one per row. What it replaces, it replaces reversibly, keeping the mapping encrypted on the user’s own computer: pseudonymization rather than anonymization, as our pages for organizations describe it.

There are Mac and Windows apps, and the policy step is chosen by IT rather than by each user. What the apps keep on disk is on the security page.

There is no OCR, so a scanned PDF is only images to it. A public agency should read our license terms before anyone signs.

If you buy nothing at all, do these six things

  1. Ask your records officer the question in writing. Are prompts public records here, and under which retention schedule.
  2. Find out who is signed in with a personal account. Not to discipline anyone, but to know where your records are sitting.
  3. Name one sanctioned tool. Any defensible choice beats an unwritten one, because the unwritten one is already consumer ChatGPT.
  4. Write the never list with your department heads. Three lines each. It is an afternoon.
  5. Decide the disclosure rule and make it narrow enough to follow. A labeling rule nobody obeys is evidence against you.
  6. Take the GovAI Coalition templates. They are free, aligned to NIST, and over 140 agencies are credited in the work behind them.

An agency that does all six is in better shape than one that bought a product and did none of them. If a control later looks worth paying for, our channel partners are where those conversations start.

Sources

Every page below was accessed on September 20, 2026. Dates are the dates the documents carry. Four of these sites refuse an automated request and load normally in a browser: the Colorado legislature, Poynter and the two City of San Jose pages.

The four assistant guides for a US reader: ChatGPT, Claude, Gemini and Copilot.

Common questions

Are ChatGPT prompts public records?

Usually yes, where the interaction relates to public business. For AI in local government, Washington State Archives answered the question directly in June 2024: a generative AI interaction, input and output, is a public record under RCW 40.14.010 when it relates to public business.

Does using a personal ChatGPT account keep it out of a records request?

No. Washington State Archives states that if you use a personal AI account to conduct business for your agency, you are creating public records, and that it does not matter whether the account is personal or issued by the agency.

Can a city redact sensitive information out of AI chat logs?

Only what an exemption covers. Records officers in Bellingham and Everett redacted some chat histories, and the reporting notes that many other records did not meet the legal threshold for redaction yet still held personal information.

Does the CCPA apply to a city or county?

Generally no. The CCPA defines a business as an entity organized or operated for the profit or financial benefit of its owners, which a public agency is not. What binds an agency is its public records law, its retention schedule and its sector rules.

Is there a federal law on AI in local government?

There is no comprehensive federal AI statute. Executive Order 14365 of December 11, 2025, sets federal policy and creates a DOJ task force to challenge state AI laws, and it ties some federal funding to a state's AI legislation.

Can a Texas city write its own AI ordinance?

Not since January 1, 2026. Section 552.003 of the Texas Business and Commerce Code, added by HB 149, states that the chapter supersedes and preempts any ordinance, resolution, rule or other regulation adopted by a political subdivision regarding the use of AI systems.

What does Colorado's new AI law cover for public agencies?

Essential government services and public benefits are one of its covered domains. SB 26-189, signed May 14, 2026, repealed and reenacted the 2024 Colorado AI Act, and its developer and deployer duties start on January 1, 2027.

What framework should a local agency align to?

The NIST AI Risk Management Framework, released January 26, 2023, is what most US public sector templates point at, including the GovAI Coalition's. NIST states the framework is being revised as part of the White House AI Action Plan.

Where can a small agency get AI policy templates for free?

The GovAI Coalition, led by the City of San Jose, publishes an AI policy, a governance handbook, an incident response plan, an AI FactSheet and a vendor agreement. It went public on March 13, 2024, and the templates are free to adopt.

Does masking names make a prompt safe to send?

It removes identifiers, not context. A complaint about one address on one date can identify a household with no name in it, and no tool can judge that a document should not leave the building at all.